Arc / SECURITY
다중 레이어 E2EE 아키텍처
엔지니어링 방향을 공개하는 상용 보안 제품
ILLUSTRATED 1:1 FLOW · 10-SECOND PREVIEW
Encrypted here.Opened there.
A message between people. Private keys stay on the devices; servers carry ciphertext and delivery data.
- 01Encrypt on device
The message is encrypted before it leaves.
- 02Transport ciphertext
Firestore carries ciphertext and delivery data.
- 03Open on device
The recipient’s device decrypts the message.
Concept animation of one delivery path, not a recording of the app. Other paths, server-visible metadata and exceptions are documented below.
Arc system architecture
Explore the system diagram
Private keys are stored in the device Keychain / Keystore and never sent to servers. Messages to other people are encrypted on the device before they are sent. Phoenix hands out public PreKeys, Firestore carries ciphertext, receipts and delivery data, and Cloud Functions handle expiry deletion and notifications. Mesh bypasses servers.
Devices (iOS / Android / macOS)
Arc Protocol
1:1 · libsignal v0.96.2 · Rust FFI
- PQXDH
- Kyber-1024
- Double Ratchet
- Private keys
- Keychain / Keystore
- Decrypted text
- SQLite / Hive
Message text and private keys never go to servers (except AI chats, link previews)
Explore the message flows
The dots move in the numbered order. On each of these paths, message text is encrypted on the device before it is sent.
Post-quantum
1:1 message
- First time: fetch B's keys
- Encrypt on the device
- Send ciphertext only
- Notify (no content)
- Decrypt on B's device
- Read / decrypt receipts
Only A's and B's devices can read the text
1:1 is post-quantum (PQXDH). Group messages are not (shared key + X25519 ECIES). On Mesh, nearby Arc phones may forward the ciphertext without being able to read it. Routed relay is in development.
Arc Protocol — 1:1 encryption pipeline
PQXDH
Key agreement with X25519 + Kyber-1024 (post-quantum)
Double Ratchet
A new key for every message
AES-256-GCM
Encrypts message bodies and media
Technology stack

App
Flutter 3.44 / Riverpod 2.6 / Rust FFI (libsignal v0.96.2)
Key distribution API
Elixir / Phoenix on Google Cloud Run (europe-west1)
Delivery and auth
Firebase (Auth / Firestore / Storage / Functions / FCM / App Check / Crashlytics)
Mesh
BLE implementation (Dart + Android Kotlin + iOS Swift, in-house, beta)
Technical specifications
The four encryption layers
Arc core specification
Arc's core specification is ML-KEM-1024/PQXDH, E2EE for 1:1 and group chats, IGF, and offline Mesh. This Security page documents the scope and technical details.
PQXDH 키 교환
엔지니어링 방향을 공개하는 상용 보안 제품
Double Ratchet
엔지니어링 방향을 공개하는 상용 보안 제품
AES-256-GCM 암호화
엔지니어링 방향을 공개하는 상용 보안 제품
XEdDSA 서명 (libsignal)
엔지니어링 방향을 공개하는 상용 보안 제품
ML-KEM-1024 파라미터
POST-QUANTUM
NIST FIPS 203 표준화 양자 내성 키 캡슐화 메커니즘.
| 알고리즘 | ML-KEM-1024 (via libsignal-client) |
|---|---|
| NIST 보안 레벨 | Security category 5 |
| 클래식 보안 | 2^128 bit (X25519) |
| 양자 보안 | NIST security category 5 |
| 기반 | Module Lattice (FIPS 203) |
| 공개 키 크기 | 1,568 bytes |
| 비밀 키 크기 | 3,168 bytes |
| 암호문 크기 | 1,568 bytes |
컴플라이언스 & 표준
NIST CSF 2.0
NIST 프레임워크. 6개 기능으로 사이버 리스크를 체계적으로 관리.
NIST SP 800-53
연방 보안 통제. FedRAMP 기반.
FIPS 140-3
엔지니어링 방향을 공개하는 상용 보안 제품
NIST SP 800-175B
암호화 알고리즘 선택 가이드. FIPS 203 기반.
ISO/IEC 27001
국제 ISMS 인증. B2B/B2G 신뢰 기반.
GDPR
EU 일반 데이터 보호 규정. 세계 최고 수준의 보호 기준.
UK Cyber Essentials+
영국 정부 인증 사이버보안 인증.
NCSC Cloud Security
영국 NCSC 14원칙. 클라우드 보안 평가 기준.
미국 NIST, EU GDPR, 영국 NCSC, ISO가 공개한 지침을 참고해 설계했습니다. 인증이나 제3자 감사를 받은 것은 아닙니다.
